ByteG8 VPN is operated by Sigmrbyte Ltd under the SigmrByte brand. In this notice, “ByteG8”, “we”, “us”, and “our” mean the ByteG8 service operator. Our primary website is byteg8.sigmrbyte.com.
For privacy questions and rights requests, contact support.byteg8@sigmrbyte.com. This notice does not apply to third-party services such as Google Play, the Apple App Store, or websites you visit through the VPN. Those providers publish their own notices.
If you create or use a ByteG8 account, we process your email address, account identifier, email verification state, account status, password hash, account creation time, and last login time. We do not store your password in plain text.
To keep sessions secure, we issue access and refresh tokens. The backend stores a hash and security metadata for refresh tokens, not the raw refresh token. Email verification and password reset requests use one-time token records.
The mobile and desktop clients may send a random installation identifier, platform, app version, locale, and an optional device identifier. A device may be linked to an account so that entitlement and connection access work across supported platforms. Guest mobile use can remain device based where that feature is available.
For the desktop trial, the client supplies a one-way fingerprint value so we can enforce the trial rules. We do not need the raw hardware details represented by that value.
To provide a VPN connection, we process technical connection records such as the selected server, protocol, issued credential metadata, assigned tunnel address, connection state, issue and revocation times, and account or device association. These records allow us to provision, renew, revoke, and troubleshoot access.
While a connection is active, the client may send heartbeats and cumulative usage counters. These can include session start and last-seen times, bytes sent and received, and aggregate counters for DNS filtering, ads, trackers, or malware blocked on the device. They do not include the names of DNS queries, destination URLs, browsing history, or the contents of your traffic.
If you contact support or submit feedback, we process the message, issue category, the email address you choose to provide, installation identifier where supplied, platform, app version, operating-system version, device model, and submission time. We use this information to respond, investigate issues, and improve reliability.
For mobile store purchases, we may process the store purchase token or transaction identifier, product identifier, subscription state, expiry, and the account or installation association needed to verify entitlement. Payment details remain with the relevant app store.
Where the rewarded-ad feature is enabled and you choose to watch an ad, Google AdMob may process advertising identifiers and standard device, network, and ad interaction signals. If you do not request a rewarded ad, the ByteG8 rewarded-ad flow does not call AdMob for that feature.
For selected sensitive actions, the app may request a device integrity verdict from Google Play Integrity or an equivalent platform service. We use the result to detect tampering and abuse. Short-lived nonce and verification records may be created for this purpose.
Our web and API infrastructure may record an IP address, request path, method, response status, request identifier, timestamp, and timing information. We use these logs for security, rate limiting, troubleshooting, and service operations. They are not used to create a history of the websites you visit through the VPN.
The account portal stores authentication tokens in browser local storage so it can keep you signed in. You can sign out or clear site data to remove them from the browser. The portal does not need an advertising profile to provide account features.
Network operators and third-party services may still process information as part of delivering internet traffic, and websites may identify you through their own accounts, cookies, or tracking systems. A VPN does not override those services’ practices.
Depending on the context and your location, our legal bases include performance of a contract, compliance with legal obligations, our legitimate interests in operating a secure service, and consent for optional features such as rewarded advertising. Where we rely on consent, you can withdraw it without affecting processing already carried out lawfully.
We do not sell your personal information for money. We share only what is needed for the purposes described in this notice, including with:
If ByteG8 is reorganised, acquired, or transferred, information may be transferred as part of that transaction subject to appropriate confidentiality and this notice or a replacement notice.
We keep information only for as long as it is needed for the purpose collected, security and fraud prevention, account administration, dispute handling, or legal and financial recordkeeping. Retention varies by record type.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information. You may also have the right to withdraw consent and to complain to a data protection authority.
Signed-in users can request an account export or permanently delete their ByteG8 account through the account deletion control in a supported app or account interface. Password confirmation may be required. If the control is unavailable, contact support.byteg8@sigmrbyte.com with the email address used for the account. We may ask for information needed to verify your identity.
When an account deletion request is completed, we delete the account profile, email address, password hash, login state, refresh and email tokens, account-device links, local subscription linkage, and desktop trial records. Google Play and Apple purchase records and device entitlements are unlinked from the deleted account. Devices can remain in the system for guest use without the deleted account association.
Some limited information may remain anonymised or retained where necessary for security, fraud and trial-abuse prevention, purchase disputes, accounting, tax, legal claims, or other legal obligations. Google Play and Apple may retain transaction and billing records under their own policies. Deleting a ByteG8 account does not cancel a subscription with an app store.
Account deletion requests and other rights requests are handled within the period required by applicable law.
Residents of the United Kingdom, European Union, and European Economic Area may contact their local supervisory authority. UK residents can contact the Information Commissioner’s Office. Residents of jurisdictions with sale or sharing opt-out rights can contact us to exercise those rights. We do not sell personal information for money.
Where the EU General Data Protection Regulation (GDPR) or the UK General Data Protection Regulation (UK GDPR) applies, ByteG8 acts as the controller for the personal information described in this notice. We identify the purposes and lawful bases for processing in Section 4, the recipients and international transfers in Sections 5 and 9, and the retention approach in Section 6.
Under the GDPR or UK GDPR, you may have rights to be informed, access, rectification, erasure, restriction, objection, and data portability. Some rights are subject to legal conditions and exceptions. To exercise a right, email support.byteg8@sigmrbyte.com. We may request reasonable information to verify your identity and will respond within the period required by law.
ByteG8 and our service providers may process information in the United Kingdom, European Union, United States, and other countries where those providers operate. When required, we use appropriate safeguards for international transfers, such as an adequacy decision, standard contractual clauses, or an equivalent lawful mechanism.
We use measures appropriate to the information and risks involved, including encrypted connections, access controls, password hashing, token hashing, limited administrative access, monitoring, and backups. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
If you believe your account or personal information has been compromised, contact us promptly and change your password where possible.
ByteG8 is not directed to children below the minimum age required to use the Service in their jurisdiction. We do not knowingly collect personal information from a child without the consent required by law. If you believe a child has provided information to us, contact us so we can investigate and delete it when appropriate.
We may update this notice when our Service, providers, data practices, or legal obligations change. We will update the effective date and provide additional notice for material changes where appropriate. The version shown on this page applies from its effective date.
For privacy questions, rights requests, or complaints, email support.byteg8@sigmrbyte.com or visit byteg8.sigmrbyte.com/support.